Threat Database Backdoors Backdoor.Spy.Agent.QE

Backdoor.Spy.Agent.QE

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 16,730
Threat Level: 60 % (Medium)
Infected Computers: 120
First Seen: May 17, 2023
Last Seen: January 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Backdoor.Spy.Agent.QE
Signature status: No Signature

Known Samples

MD5: 941fc5723e659f2cb1ec31143db8afd1
SHA1: 8e39f50457623cc7722a8c04868b8dddee3bf730
SHA256: B1C6EDE43B4144ADA268F9A05CC35F68CCFA08561C8D0A6CC6BE2B9D1B9A5132
File Size: 328.70 KB, 328704 bytes
MD5: c0c27a980406fc23dcc6105a324a649b
SHA1: a0d40ae8dde3820398c9ce3c4d1c8beac9d8f3ab
SHA256: 798A8713DD5974ED9A5D6221A7E4E9FA7D7F98BA3684471737ADD1181D89E1D9
File Size: 2.08 MB, 2084864 bytes
MD5: 1871ed4f8fe283e8a7d1d467ec500a2a
SHA1: f222a32e0ea742c41634967028769ebde9ce5f38
SHA256: 2F5301DA57470241777CA13FFB31A4A8C91BA7E8CF3E8AFC69B230C32EADB508
File Size: 199.17 KB, 199168 bytes
MD5: f35e814b33572a89cf185fd015e84c82
SHA1: 85f72ccda9d92de598e062b6573605e509ed7812
SHA256: 26000DBC42937B8BD74E2FDD98260B3F776E4913840EFA05CA02BEBE185D4D13
File Size: 213.50 KB, 213504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • LunaTranslator shareddllproxy v5.33
  • LunaTranslator v7.11
  • LunaTranslator v10.5
Company Name 156608225
File Description
  • Lucy 快速启动
  • LunaTranslator
  • LunaTranslator shareddllproxy
File Version
  • 10.5.9.8
  • 7.11.4.0
  • 5.33.0.0
  • 1.8.0.0
Internal Name
  • Lucy
  • LunaTranslator
  • LunaTranslator shareddllproxy
Legal Copyright
  • Copyright 2023
  • HIllya51 (C) 2024
  • HIllya51 (C) 2025
Original Filename
  • Lucy.exe
  • LunaTranslator
  • LunaTranslator shareddllproxy
Product Name
  • Lucy 快速启动
  • LunaTranslator
  • LunaTranslator shareddllproxy
Product Version
  • 10.5.9.8
  • 7.11.4.0
  • 5.33.0.0
  • 1.8.0.0

File Traits

  • HighEntropy
  • imgui
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 717
Potentially Malicious Blocks: 108
Whitelisted Blocks: 604
Unknown Blocks: 5

Visual Map

0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 x x x 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 x x x x x x x 0 0 x x x x 0 0 0 x ? x x x x x x x x x x 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 x 0 x x x x 0 x 0 0 0 x x x 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 x x x x x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 3 1 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 x x 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 1 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Process Shell Execute
  • ShellExecute

Shell Command Execution

runas c:\users\user\downloads\a0d40ae8dde3820398c9ce3c4d1c8beac9d8f3ab_0002084864 main

Trending

Most Viewed

Loading...